3 ms·
I've started handling the security inbox at Buffer now and we use a normal email approach. I can honestly say that the experience is pretty much the same and I
by nstart 6y ago
I've started handling the security inbox at Buffer now and we use a normal email approach. I can honestly say that the experience is pretty much the same and I feel like the issues you describe are independent of Hackerone (perhaps the scale increases?).
From my end, there are a lot of trivial things I have to go through where it's low effort on the researcher end (And I've even had automated searches where the researcher has sent mails to us assuming we'd have the same issue because of some similar HTTP Header or something similar). Thankfully I've gotten faster at keeping these out but it still takes up more time than needed.
From the researcher end, I assume it's frustrating where they put in the effort to craft a well documented mail and I have to inform them that it's a duplicate or known issue that we are currently working on a fix for. It's a hard call and I'll often have to use a judgement call on these. But it's made harder still when I'll suddenly see an issue that has existed for a long time be reported by a single researcher. And then in a matter of two days 3 to 4 other researchers will pop up with the exact same issue leading me to believe that either there's different accounts under the same name, or some kind of researcher group that works together in sharing findings (And maybe bounty).
Basically, I'm not sure how much this is a HackerOne issue vs a general bounty program pain ¯\_(ツ)_/¯